On Fri Sep 4, 2026 at 3:37 PM CEST, Jakub Szczudlo (Nokia) wrote: > Backport patch to fix CVE-2026-5419. > > References: > https://nvd.nist.gov/vuln/detail/CVE-2026-5419 > > Upstream fix: > > https://gitlab.com/gnutls/gnutls/-/commit/1e627aa5ad95c6dc0518d94e9a009997b081a1ab > > Tested with ptes > > Signed-off-by: Jakub Szczudlo <[email protected]> > --- > .../gnutls/gnutls/CVE-2026-5419.patch | 247 ++++++++++++++++++ > meta/recipes-support/gnutls/gnutls_3.8.12.bb | 1 + > 2 files changed, 248 insertions(+) > create mode 100644 meta/recipes-support/gnutls/gnutls/CVE-2026-5419.patch > > diff --git a/meta/recipes-support/gnutls/gnutls/CVE-2026-5419.patch > b/meta/recipes-support/gnutls/gnutls/CVE-2026-5419.patch > new file mode 100644 > index 0000000000..f75aff35db > --- /dev/null > +++ b/meta/recipes-support/gnutls/gnutls/CVE-2026-5419.patch > @@ -0,0 +1,247 @@ > +From 2f3732538d7d8e1ae255ca68c20efc61a1d5b3e2 Mon Sep 17 00:00:00 2001 > +From: Daiki Ueno <[email protected]> > +Date: Fri, 4 Sep 2026 09:17:32 +0000 > +Subject: [PATCH] gnutls_cipher_decrypt3: make PKCS#7 unpadding branch free > + > +This tries to make the logic of PKCS#7 padding removal constant-time, > +by removing potential branching operations. > + > +CVE: CVE-2026-5419 > +Upstream-Status: Backport > [https://gitlab.com/gnutls/gnutls/-/commit/1e627aa5ad95c6dc0518d94e9a009997b081a1ab] > + > +Backport Changes: > +- Adjusted the upstream hunk to match the GnuTLS 3.8.12 code layout. > +- Drop .gitignore from the backport. > + > +Reported-by: Doria Tang of Stony Brook University > +Fixes: #1815 > +Fixes: CVE-2026-5419 > +Fixes: GNUTLS-SA-2026-04-29-13 > +CVSS: 3.7 Low CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N > +Signed-off-by: Daiki Ueno <[email protected]> > +Signed-off-by: Jakub Szczudlo <[email protected]> > + > +--- > + lib/crypto-api.c | 53 ++++++++++++++++------ > + lib/libgnutls.map | 2 + > + tests/Makefile.am | 2 +- > + tests/pkcs7-pad.c | 109 ++++++++++++++++++++++++++++++++++++++++++++++ > + 4 files changed, 152 insertions(+), 14 deletions(-) > + create mode 100644 tests/pkcs7-pad.c > + > +diff --git a/lib/crypto-api.c b/lib/crypto-api.c > +index 01539d5..7749fcd 100644 > +--- a/lib/crypto-api.c > ++++ b/lib/crypto-api.c > +@@ -497,6 +497,38 @@ error: > + } > + return ret; > + } > ++/* If succeeds, returns the number of padding bytes to be removed; > ++ * zero otherwise. > ++ */ > ++ unsigned int _gnutls_pkcs7_unpad(const uint8_t *block, unsigned int > block_size) > ++ { > ++ uint8_t padding = block[block_size - 1]; > ++ volatile unsigned int mask = ~0; > ++ volatile unsigned int count = 0; > ++ > ++ /* Count consecutive PADDING bytes from the end, in a > ++ * constant-time manner. > ++ */ > ++ for (size_t i = block_size; i > 0; i--) { > ++ volatile unsigned int mask2; > ++ > ++ mask2 = -(unsigned int)(block[i - 1] == padding); > ++ mask2 &= -(unsigned int)(count < padding); > ++ > ++ /* MASK is initially ~0 and will be flipped to 0 upon first > ++ * non-padding bytes. > ++ */ > ++ mask &= mask2; > ++ count += 1 & mask; > ++ } > ++ > ++ /* PADDING == 0 is effectively excluded here, given COUNT > ++ * will never be 0. > ++ */ > ++ mask = -(unsigned int)(count <= block_size); > ++ mask &= -(unsigned int)(count == padding); > ++ return count & mask; > ++ }
Hello, In this added _gnutls_pkcs7_unpad function, in every lines, a space was added just before the code from the upstream patch. Why? Is this the "Adjusted the upstream hunk to match the GnuTLS 3.8.12 code layout." change? If those space were added by mistake, can you send a v2 without them? Thanks! -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#245391): https://lists.openembedded.org/g/openembedded-core/message/245391 Mute This Topic: https://lists.openembedded.org/mt/121085938/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
